9.3

CVSS4.0

CVE-2025-8861 - Changing|TSA - Missing Authentication

TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents.

📅 Published: Aug. 29, 2025, 3:28 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-9608 - Portabilis i-Educar Formula de Cálculo de Média view sql injection

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/view of the component Formula de Cálculo de Média Page. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The expl…

📅 Published: Aug. 29, 2025, 3:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 5 p.m.

5.3

CVSS4.0

CVE-2025-9607 - Portabilis i-Educar Tabelas de Arredondamento view sql injection

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of the component Tabelas de Arredondamento Page. Executing manipulation of the argument ID can lead to sql injection. The attack may be launche…

📅 Published: Aug. 29, 2025, 3:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 5 p.m.

5.3

CVSS4.0

CVE-2025-9606 - Portabilis i-Educar agenda_preferencias.php sql injection

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing manipulation of the argument cod_agenda results in sql injection. The attack may be initiated remotely. The exploit is…

📅 Published: Aug. 29, 2025, 2:32 a.m. 🔄 Last Modified: Sept. 2, 2025, 5 p.m.

9.3

CVSS4.0

CVE-2025-9605 - Tenda AC21/AC23 GetParentControlInfo stack-based overflow

A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has bee…

📅 Published: Aug. 29, 2025, 2:02 a.m. 🔄 Last Modified: Sept. 3, 2025, 4:10 p.m.

7.7

CVSS3.1

CVE-2025-58323 -

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks.

📅 Published: Aug. 29, 2025, 1:41 a.m. 🔄 Last Modified: Oct. 16, 2025, 7:09 p.m.

8.6

CVSS3.1

CVE-2025-39247 -

There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

📅 Published: Aug. 29, 2025, 1:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-39246 -

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access.

📅 Published: Aug. 29, 2025, 1:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-39245 -

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

📅 Published: Aug. 29, 2025, 1:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-9604 - coze-studio aes.go hard-coded key

A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument AuthSecretKey/StateSecretKey/OAuthTokenSecretKey leads to use of hard-coded cryptographic key . It is possible t…

📅 Published: Aug. 29, 2025, 1:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4092 of 34,919
« previous page » next page
Filters